Help! Can't run exe files!

Discussion in 'Malware Help (A Specialist Will Reply)' started by lpontius1, Mar 31, 2010.

  1. lpontius1

    lpontius1 Private E-2

    Started getting popups from XP Antivirus 2010, so I started the READ ME instructions. I got all the way through the first steps and up to the XP cleaning procedure. I ran SAS & restarted the computer, but now I can't run any exe files!

    When I try, I get a message saying "Choose the program you want to use to open this file" and then a list of programs. I've tried running in Safe Mode, but there is no change.

    I'm running AVG Free 8.5 on this computer.

    Please help!!!
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You need to attach the log from running SAS.

    Also try this, scroll down to the ninth fix in the list, until you see the EXE file Association fix.

    Windows® XP File Association Fixes
     
  3. lpontius1

    lpontius1 Private E-2

    Thank you, Thank you, Thank you!! I was getting really frustrated with that!

    So I'm attaching my SAS log; should I go ahead and run the rest of the tools also?
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes please! :)

    Also...

    Important Notice: A new version of SUPERAntiSpyware is available.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this log later.
     
  5. lpontius1

    lpontius1 Private E-2

    OK I did ask you requested & downloaded the new version of SuperAntiSpyware. I'm attaching the new log for that as well as the logs from the other tools.

    Oh and all of a sudden when Windows starts I get this error message: "Your SQL Server installation is either corrupt or has been tampered with (unknown package id). Please rerun Setup." I'm not sure what this means... Any ideas?

    Please let me know where to go from here. Thanks!
     
  6. lpontius1

    lpontius1 Private E-2

    Oops! Here are my most recent logs.
     

    Attached Files:

  7. lpontius1

    lpontius1 Private E-2

    And here is my MGlogs.zip file.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are using an outdated avg. Version 9 is the most current which you can upgrade to if you choose to stick with it.

    Now before I give you a fix, I would like you to answer my questions below:

    Did you purposely place this into your hosts file?
    And did you knowingly place these into your TZ and trusted IP Range?

    Also, please ensure you tell me how your PC is behaving now after the scans.
     
  9. lpontius1

    lpontius1 Private E-2

    I was getting ready to switch antivirus programs anyway when I started having problems, so I will just do it once we are finished here.

    To answer both of those questions, Yes. I need to have them for some programs I run for work.

    Otherwise, my computer seems to be running much better & aside from the SQL server problem I mentioned earlier (when Windows starts I get this error message: "Your SQL Server installation is either corrupt or has been tampered with (unknown package id). Please rerun Setup."), I don't think I'm having any other issues. Thanks so much!
     
  10. lpontius1

    lpontius1 Private E-2

    I just noticed that Yahoo Messenger won't load either. I get a message saying, "The application failed to initialize properly (0xc0150002). Click on OK to terminate the application."
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not topic for the malware removal forum I'm afraid. Let's continue on with what we are focussing on:

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    C:\Documents and Settings\your username\Local Settings\Application Data\J7Qo
    C:\Documents and Settings\All Users\Application Data\J7Qo
    C:\Documents and Settings\Michael Blackburn\Templates\J7Qo
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\NoExplorer]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  12. lpontius1

    lpontius1 Private E-2

    OK, here are my latest logs. Combofix had a newer version, so I downloaded it.
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just use windows explorer to find and delete the below bold file:

    If it goes away nicely, then you can follow final steps:

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
    Last edited: Apr 8, 2010

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds